With an intermediate CA certificate held in Key Vault, Azure Firewall Premium can decrypt outbound and east-west TLS traffic, inspect it and encrypt it again.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains TLS inspection in context, with comparison tables and the common traps.
Terms in this definition
- Intermediate CA certificate
Used by Azure Firewall Premium to sign server certificates on the fly during TLS inspection, this CA certificate must be exportable and is kept as a Key Vault secret. A user-assigned managed identity gives the firewall access, and clients need to trust the root above it.
- Access policies
Older permission model for Key Vault, now superseded by the Azure RBAC model.
- Azure Firewall Premium
Top Azure Firewall SKU, which builds on Standard with IDPS, TLS inspection, URL filtering and web categories; using those features requires a firewall policy on the Premium tier.
- TLS
Transport Layer Security, the encryption protocol for traffic like HTTPS and Bastion sessions over port 443. On a storage account, minimumTlsVersion fixes the oldest accepted version without opening any network access.